Ask yourself a question, would you buy a humanoid robot from a supplier you wouldn’t trust with a laptop?
It is a key question the robotics industry needs to consider now.
Only last week the US made a significant step in that direction. The Federal Communications Commission added foreign-produced advanced robotic devices to its Covered List following a national-security determination. The definition is broader than humanoids alone, covering certain autonomous mobile robots, including humanoids and quadrupeds, that combine environmental sensing, network connectivity and software-controlled movement.
The central issue here is not that the US is restricting foreign robotics, but why?
The determination points towards concerns around supply-chain vulnerabilities, cybersecurity and the potential impact on critical infrastructure. Reuters reports that FCC Chairman Brendan Carr has framed the restrictions as an attempt to prevent potentially compromised foreign technology becoming embedded across strategically important parts of the US economy.
For anyone developing, deploying or investing in humanoid robotics, this is a warning worth paying attention to.
Where a robot is assembled matters, however knowing where it was put together does not tell you where its critical technology came from, or who supplied it, or who ultimately controls it.
A humanoid robot could contain hundreds of globally-sourced components, such as:
- Motors.
- Cameras.
- Sensors.
- Processors.
- Firmware.
- Operating systems.
- Cloud services.
- AI models.
- Developer libraries.
- Software update infrastructure.
So when someone says, “Our robots are manufactured in the UK,” the next question should be:
“Where did everything inside them come from?”
The NCSC has essentially been making the same argument about software and AI supply chains. Its guidance recommends that organisations assess and monitor suppliers throughout the lifecycle and maintain visibility of components including models, data, software libraries, middleware and external APIs.
The problem is that modern robotics makes this considerably harder.
A vulnerability in a library is one aspect, but a compromised component inside a humanoid that has cameras, microphones, network connectivity and the ability to physically interact with its environment is something else.
Research published in 2025 examining a commercial humanoid robot found issues including persistent telemetry connections and weaknesses in the implementation of its security architecture. Separate research mapped 39 known attacks and 35 defences across seven layers of the humanoid ecosystem, from hardware through to human interaction.
And this is not just a theoretical concern.
On the 10th August 2026, reporting has emerged that cameras installed on British naval drones were found during a routine cyber vulnerability assessment to be communicating with an internet address in China. Critically, the Ministry of Defence has reported that there was ‘no evidence that MOD data or systems were compromised or transmitted externally, and the affected connectivity has since been addressed’. The report highlights that vulnerability processes identified the activity and that robust assurance processes should always be applied.
The important point here is ensuring that the components that make up any product or service are fully understood, and acknowledged that the customer did not have complete visibility of what the component was doing.
Cybersecurity is not about assuming that every foreign component is compromised.
It is about being able to prove what your technology is doing.
Can you identify every component?
Can you trace its provenance?
Can you verify its firmware?
Can you understand where telemetry is going?
Can you control who can update it?
Can you prevent unexpected outbound connections?
Can you replace the component if the geopolitical situation changes?
And perhaps most importantly:
Can you answer those questions before your customer asks them?
For a robotics company, these questions can feel like problems for later.
They are not.
The companies that eventually sell into major manufacturers, healthcare organisations, critical infrastructure or Government will increasingly find that security assurance becomes part of the product.
This is where OppiSec sees a real opportunity to help.
We work with emerging technology companies to bring together Secure by Design, AI security, cloud assurance, supply-chain security, vulnerability management and governance before those requirements become a barrier to growth.
For a humanoid robotics company, that could mean building a component inventory and SBOM.
It could mean threat-modelling the robot and its supporting cloud environment.
It could mean assessing the security of suppliers several tiers down the chain.
Or it could simply mean answering a customer’s security questionnaire with something more convincing than “Our supplier assures us it’s secure.”
The future robotics market may not be divided simply between the robots that are intelligent and those that are not so.
It may be divided between the robots that are trusted and those that can be
And that could become one of the biggest competitive advantages in the industry.
A humanoid robot is not a machine. It is a supply chain that can think, see, hear, move and connect to the outside world.
OppiSec is a Cambridge-based Cyber Security Consultancy built on more than two decades of experience across UK Intelligence, Defence, and Security. Our foundations lie in safeguarding sensitive information and protecting the critical assets that underpin public services. Years spent defending against nation‑state adversaries have given us a deep understanding of how cyber-attacks are crafted and deployed. We apply that high-level insight to develop practical, effective controls that strengthen your security posture and protect your data, systems, and services. Call us to discuss your requirements 01223 375324.
FCC Covered List – July 2026
Reuters – US restrictions on Chinese technology and robots
NCSC – Secure AI system development and supply chains
https://arxiv.org/html/2509.14096v1
https://www.independent.co.uk/news/uk/home-news/royal-navy-drone-cameras-china-mod-b3030094.html


